# August remediation / September audit reconciliation

**Latest implementation status (2026-09-05):** All R01–R22 are addressed. Vitest 5 and native Windows/macOS QA are recorded in the [remediation and QA report](AUDIT_REMEDIATION_2026-09-05.md). External release gates remain open; earlier findings/checkpoints below are retained as historical evidence.

**Checked:** 2026-09-05. **Result:** remediation exists and is preserved; not committed on master at review start.

[Finalized August review](CODEBASE_REVIEW_FINALIZED_2026-08-31.md) · [Recovered normalized cross-review](CODEBASE_REVIEW_COMBINED_2026-08-31-gpt-5.6-sol.md) · [September audit](CODEBASE_AUDIT_2026-09-05.md)

[HTML companion](REVIEW_RECONCILIATION_2026-09-05.html)

**Implementation checkpoint (2026-09-05):** Commit `346f272` preserves the August remediation, restored evidence, and both September reports. R04 is fixed in `979152e`; R01/R02 are fixed in `bf43eeb`. R21 was resolved by restoring the historical reports. The remaining 18 findings are tracked in Atlas. The recovery changes passed the full Go race suite, lint, and all seven Linux native updater cases; the CI script passed all six targets. Windows/macOS native reruns remain release gates. Legacy unauthenticated update journals require manual recovery; see [Troubleshooting](TROUBLESHOOTING.md#update-recovery-requires-manual-attention).

## Commit status and provenance

The August remediation was not committed to master. At reconciliation start, master and HEAD remained bdfb31b95030c2d992e5cfc4cb0ba5bada368d1b, dated August 30. The subsequent working-tree changes included 195 modified tracked paths and 89 original untracked files; the September audit added two report files. There were no staged changes. No remote was fetched or pushed during this reconciliation.

T3 saved automatic checkpoint commits outside ordinary branch history. The final August checkpoint is fa0a678846ccd10fa162f8caaba1258f98d37226, dated August 31, 22:18 EDT. Comparing Git blob bytes directly with working files—not git diff, which omits untracked file contents—found 797 identical existing files, one changed generated file (TRACKING.md), and 16 missing review artifacts. Thus the production code, tests, dependencies, build scripts, and finalized August report examined by the September audit are exactly the final August checkpoint contents.

The 16 missing artifacts were eight scratch reviews under .opencode/reviews and four historical report pairs under docs. The eight maintained Markdown/HTML report files were recovered byte-for-byte from that checkpoint as part of this reconciliation. Scratch reviews were left out of the project tree. No application code was changed before the baseline commit. Git records the checkpoint author as T3 Code; it cannot independently attribute uncommitted lines to a model. The report attribution to GPT-5.6 Sol with GLM-5.3 contributions is consistent with the recovered documents.

The September audit therefore builds directly on the August fixes. Its R01–R22 are residual findings against those fixes, not a review accidentally run against pre-remediation HEAD. Most are older defects or incomplete integration; the table below distinguishes them from regressions introduced while fixing another issue.

## Quality of the August fixes

The remediation was substantial and generally worth preserving. It replaced several unsafe patterns with explicit ownership, atomic persistence, native replacement, signed-selection proof, resource leases, ordered TUI streams, and bounded observation. The implementation and failure-injection tests support those improvements. The claim that 98 root defects are fully closed is too broad for several integration boundaries, and it must not be read as release qualification. The recommended response is targeted repair on top of this baseline, not reverting the remediation.

| August findings / task | Verified improvement | Qualification and September follow-up |
| --- | --- | --- |
| CH-01–CH-04 / e8edb50e | Windows uninstall stops elevating mutable archive scripts, deletes an explicit payload inventory, and preserves unrelated files; TUI carries exact app identity/path; editors resolve the selected config tree. | Preserve all safeguards. R09 identifies an absent migration path for historical/adopted Windows payloads, not a reason to return to broad deletion. |
| CH-08–CH-10, CH-17, CH-25 / e63624dc | Config mutations persist candidates before publishing them; read errors preserve last-good state; reset/restore/language operations require durable recovery copies and atomic publication. | Sound corrections to the reported mutation/read/backup failures. R12/R13 concern inherited mpv.conf grammar/typing defects rather than failure of candidate-before-publish. |
| CH-11 / 33b25a4a | The concurrent Web probe collector exits on deadline, snapshots its test hooks, and publishes a rebuilt cache outside its write lock. | The precise collector defect was fixed. R06 reaches other, older probe paths before or outside that collector; its broader boundedness claim is incomplete. |
| CH-12, CH-16 / 527118d9 | IINA uses the returned owned mount/device with bundle validation; FFmpeg has staged verified bytes and rollback evidence retained on failure. | Preserve these improvements. Native macOS mount/signature and Windows replacement evidence still matter; R01 concerns newly added generic startup replay, not reversion of these normal-path safeguards. |
| CH-05–CH-07 / a7cae2ff | Cancellation is nonterminal until worker acknowledgement; unlike methods can conflict on shared resources; tracking failures produce partial outcomes. | Correct foundations. R07 places the new commit boundary too early; R16 bypasses the new lease on one reconciliation route; R03/R05 expose server/process ownership not covered by these job-state corrections. |
| CH-21–CH-24 / 57a2c7cf | TUI joins worker results before navigation, drains ordered output, preserves selected identity for UI changes, and consumes filter keys before dispatch. | Focused regressions pass and the changes should remain. Joining the direct worker does not independently terminate subprocess descendants (R05). |
| CH-15, CH-18–CH-20 / 6bfdc713 | The helper preserves terminal descriptors; first-render readiness gates health; new payloads are checked before execution; replacement retains a live target; missing required backups fail rollback. | These are real improvements. R02 concerns independently trusting persisted recovery state and legacy backup identity execution. Normal-path authenticated selection is not evidence that arbitrary recovery JSON is trusted. |
| CH-13, CH-14, CM-19 / 75ddd84a | Generation consumes reviewed tag-bound pins and local manager bytes; private-key variables are rejected; signing is delegated across a documented OIDC boundary. | Repository controls are present. The isolated service, real approved lock, protected policy and immutable publication are correctly left externally gated; no live provisioning was inferred. |
| CM-02/03/30–33/54/55 / b0ce0058 | User-wide target-set locking, earlier durable intent, orphan cleanup, child identity/wait, durable outcome history, opaque verified selections and anti-replay/key lifecycle checks are implemented. | Preserve them. R02 remains a recovery-store trust boundary; source-authenticated selection and a journal field bearing a key ID are different kinds of evidence. |
| CM-01/29 / 7b114046 | Native archive inventory validation and private staging precede live writes; cross-process installer locks and persistent journals replace memory-only rollback. | Archive/staging corrections are sound. R01 is a defect in the newly added journal replay ordering. R10/R11 show that early UI snapshots and metadata are not fully included in durable ownership. |
| CM-05/06/09/12–14 / 7ae284c4 | File locks serialize cross-process manager/history updates; requests validate all fields before one write; backup containment and UI-migration CAS/journaling are implemented. | Good per-operation primitives. R10 uses a separate old UI-update snapshot path outside the editor CAS boundary; R11 concerns component metadata, not the specific ModernZ migration transaction. |
| CM-17/24/41/47–49 / 96f6eca6 | CLI conflicts and unsupported paths are rejected; PATH mutations compensate errors; quote-aware comment parsing and script-option metadata are preserved; browser launch follows listener readiness. | The reported quote/hash and startup ordering corrections remain useful. R12/R13 need profile-aware and typed mpv.conf parsing beyond the narrower comment lexer. |
| CM-07/08/10/21–23/25/26 / b5874805 | SSE connections close before HTTP drain and reconcile snapshots; terminal queues, password dispatch, Config dirty state, request ownership and immutable locale publication are improved. | CM-07 fixes connected SSE shutdown, not background installer shutdown (R03). R14 is an older Alpine initialization problem, not evidence that the password double-dispatch fix failed. |
| CM-04/27/28/42–46 / b2b8ccff | Windows discovery is non-executing; observations distinguish absence from uncertainty; elevated MPC-QT install waits and verifies discovery; CPU/GPU/hotkey/locale corrections are present. | MPC-QT installation is fixed; R08 is its older, separate uninstall function. R06 still reaches legacy version probes; R16 exposes a second reconciliation entry point. |
| CM-34–40/56 / 9e257733 | TUI handles worker panics, correct progress fractions, bounded/coalesced output, resizing, stable update identity, offline startup, Unicode and terminal sanitization. | Preserve the TUI output work. R15 concerns the common runner partial-line buffer and Web retained arrays, so it does not invalidate the bounded TUI model itself. |
| CM-11/15/18–20/50–53 / 22a13f11 | Resource generation, digest-pinned images, bounded generator downloads, canonical/protected publication controls, native-evidence binding, trusted builds and notices are implemented. | R04 finds an inherited target-environment bug in the old verifier invocation and the same error in new go-winres invocations. Direct cross-build/resource tests did not execute the full shared CI job. |
| CM-16, CL-01–CL-20 / 78a290dc | CSP/externalized scripts, reduced motion, local release frontend gates, script CAS, SSE limits, correctness Staticcheck and many focused hardening fixes are present. | R15 adds a bound missing from new line framing; R18 distinguishes whole-program exported reachability from Staticcheck U1000; R19/R20 identify inherited scaffolding/wrappers; R21/R22 improve recoverable evidence and instruction drift. |

## Cross-reference for every September finding

| September | Relationship to August | Origin established by HEAD/checkpoint comparison | Disposition |
| --- | --- | --- | --- |
| R01 | CM-29 installer journals | New transaction_journal.go; recovery removes target before testing backup existence. | New replay defect in a useful durability feature; fix replay, retain journals/locks/staging. |
| R02 | CH-18/20; CM-30/55; CL-12 | Journal trust gap existed before August; new original-evidence/legacy-capture logic executes the untrusted backup during recovery validation. | Residual trust gap with earlier execution exposure. Do not weaken new payload authentication or normal rollback evidence. |
| R03 | CM-07; CH-05–07; CL-18 | HEAD already had HTTP-only shutdown; August adds SSE/root signaling but no worker join. | Inherited uncovered lifecycle gap. SSE shutdown correction remains valid. |
| R04 | CM-11/52; release task | HEAD already ran verify-manifest under target GOOS/GOARCH; new go-winres calls repeat it. | Inherited defect expanded by resource work. Correct host-tool environment everywhere. |
| R05 | CH-21; CL-12, related process lifetime | Generic CommandRunner already used direct CommandContext without process-tree management. | Inherited. TUI worker joins and bounded identity probes do not solve generic descendants. |
| R06 | CH-11; CM-27 | pkg/version/updates.go is unchanged; Web GetPackageVersion still starts from Background. | Incomplete caller coverage around a correctly repaired collector. |
| R07 | CH-05 | BeginCommit calls at the start of installation are new. | New restriction/regression in cancellation usability. Preserve worker-owned terminal outcomes. |
| R08 | CM-28, different operation | UninstallMPCQTWithOutput remains the old implementation; August hardened installation. | Inherited uninstall bug, not a failed fix to the installation function. |
| R09 | CH-01/02 | Ownership manifest and populated-directory refusal are new. | New compatibility gap from intentional safety policy. Add scoped migration, retain refusal for unproven files. |
| R10 | CM-29; CL-04, different path | The early UI config snapshot and staging callback order already exist in HEAD. | Inherited. Editor CAS was fixed, but UI update does not participate. |
| R11 | CM-29; CH-07, adjacent metadata | Staging-side version mutation and omitted baseline paths predate the new persistent journal; the journal does not include them. | Inherited metadata mismatch plus incomplete durable transaction scope. |
| R12 | CM-41 | Profile-unaware first-key editing already exists; August fixes quote-aware comments only. | Inherited grammar issue. Reuse the improved comment lexer. |
| R13 | CM-41, adjacent scalar typing | Comma splitting and first-item Web scalar lookup already exist. | Inherited. Add typed accessors without regressing quoted hashes. |
| R14 | CM-10/21; CL-16, distinct lifecycle | Tasks x-init and component init already coexist in HEAD; August template work externalizes scripts. | Inherited real-framework lifecycle defect. Preserve async/focus/password fixes. |
| R15 | CL-10; CM-36, different layers | Pending partial-line string is new; browser output arrays are inherited. | Mixed: new unbounded framing buffer plus older Web retention. Keep correct line framing and bounded TUI output. |
| R16 | CH-06; CM-27; CL-08 | Resource leases are new; check-updates remains outside them while sharing mutating refresh. | Incomplete integration of the new coordinator, not a need to replace it. |
| R17 | Performance opportunity adjacent to CM-05 | Per-field repeated file reads already exist. | Inherited optimization and coherent-snapshot opportunity. |
| R18 | CL-06/12/19; broad dead-code claim | The cited API families predate August. Staticcheck U1000 and whole-program exported reachability answer different questions. | Cleanup opportunity; qualify “dead-code clean,” not a claim that reported Staticcheck results were false. |
| R19 | AI-slop/test review scope | Unused interfaces and mock-only test families predate August and are unchanged. | Inherited cleanup; retain actual production failure-injection tests. |
| R20 | AI-slop/organization review scope | Repeated shortcut dispatch wrappers predate August. | Inherited focused simplification. |
| R21 | CL-19; finalized report references | All four missing source reports and HTML companions exist in fa0a678. | Resolved during reconciliation by exact restoration. Initial missing-file observation was correct; evidence is recoverable. |
| R22 | CL-19; agent workflow | Large historical root instructions predate August; that pass adds further history/status. | Accumulated documentation drift. Consolidate without losing current invariants or Atlas rules. |

## Validation and limits

The earlier September audit ran full normal/race Go suites, vet/Staticcheck, module consistency, vulnerability scans, 180 frontend assertions, embedded-vendor/Tailwind freshness and six direct application cross-builds. The checkpoint/current byte comparison proves the source under reconciliation is the same source that passed those checks. The audit also reproduced the residual defects; a green suite is not evidence against those reproductions.

This reconciliation additionally reran 22 top-level regression tests across config, installer, TUI, updater and Web, all passing. They exercise rejected persistence, last-good state, rebasing, exact ownership and unrelated-file preservation, IINA mount containment, selected app identity, ordered output and cancellation joins, release replay policy, recoverable replacement, missing backup failure and resource conflicts. These tests validate useful August fixes; they do not cover the new replay/caller gaps by construction.

No native Windows/macOS destructive operations, real power loss, production signing service, protected remote policy or release publication were executed. The existing external release tasks stay open. No blanket claim that every one of the historical 101 entries is completely fixed is made; the table assesses the implementation groups and identifies concrete residuals.

## Baseline and follow-up policy

Commit the current remediation as one baseline before further application edits, including the finalized August report, September audit, restored historical evidence, this reconciliation and Atlas-generated tracking. This preserves the actual completed work without pretending it is a release-ready state. Subsequent fixes should be separate, focused commits tied to R01–R22, starting with recovery/trust, lifecycle and CI. R21 is already resolved by recovering the evidence.

User instruction on September 5 authorizes this sequence: verify the old work, commit the existing state, then work on the new findings. Atlas reconciliation task: 806fd152-fc35-490c-a589-fb579d0bd3fe. The completed September audit remains the immutable finding record; implementation status belongs in Atlas and follow-up change descriptions.
